First published: Tue Aug 03 2021(Updated: )
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSandbox | <=3.1.4 | |
Fortinet FortiSandbox | >=3.2.0<3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24014 is a vulnerability in FortiSandbox before version 4.0.0 that allows an unauthenticated attacker to perform an XSS attack through specially crafted request parameters.
The severity of CVE-2021-24014 is medium with a CVSS score of 6.1.
CVE-2021-24014 affects FortiSandbox versions before 4.0.0, allowing an unauthenticated attacker to perform an XSS attack.
The CWE of CVE-2021-24014 is CWE-79, which represents improper neutralization of input during web page generation.
To fix CVE-2021-24014, it is recommended to upgrade FortiSandbox to version 4.0.0 or later.